« Volver al listado

CVE-2026-98044

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject legacy packet loads from callbacks

check_ld_abs() models a failed BPF_LD_ABS or BPF_LD_IND in a subprogram as an implicit return with R0 set to zero. It calls prepare_func_exit() to explore this synthesized path.

When the load is reached directly from a synchronous callback, prepare_func_exit() enforces the callback return contract and marks R0 precise. R0 is not derived from a real instruction on this path, so precision backtracking reaches the callback call with R0 still requested and triggers the "callback unexpected regs" verifier bug. A privileged program loader can therefore cause a verifier warning and an -EFAULT BPF_PROG_LOAD.

Leer descripción completaMostrar menos

These legacy packet-load instructions are deprecated. Reject them from callbacks rather than complicating their implicit-return model. Check all active frames before constructing the implicit return so nested static subprograms cannot hide the callback context.

Global functions are verified independently with a fresh frame zero, so an active-frame check cannot identify a global function called from a callback. Also check the complete subprogram call graph during stack-depth validation and reject a function containing a legacy load when any caller is a callback. This covers global and static descendants without making has_ld_abs transitive, preserving its per-function BTF return-type check. Ordinary uses outside callbacks remain supported.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98044",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337",
              "lessThan": "3484a99303912db62428494a9061212049027e57",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee861486e377edc55361c08dcbceab3f6b6577bd",
              "lessThan": "bc489c0c9b8c86bd7fac42cfd1bb152f042fca56",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee861486e377edc55361c08dcbceab3f6b6577bd",
              "lessThan": "e7d28823c662128caae63f14e16bd394916c139b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "928d354ae3557e8f755a227e67be88034eb3cd7f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "de1055e7f9e67af32b1f3376066272b04e5223c0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "37ad2bb11e9de92cb7b94548705eeedd87f7d392",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8674e2db06cff6b50f2216eed9a761d15425bb34",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d846d83bdacbd8f14fc45c63b8c1d22608452e1c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.18.42",
              "lessThan": "6.18.53",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.265",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.216",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.183",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.148",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.101",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.0.10",
              "lessThan": "7.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:33.200",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3484a99303912db62428494a9061212049027e57",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bc489c0c9b8c86bd7fac42cfd1bb152f042fca56",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e7d28823c662128caae63f14e16bd394916c139b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject legacy packet loads from callbacks\n\ncheck_ld_abs() models a failed BPF_LD_ABS or BPF_LD_IND in a\nsubprogram as an implicit return with R0 set to zero. It calls\nprepare_func_exit() to explore this synthesized path.\n\nWhen the load is reached directly from a synchronous callback,\nprepare_func_exit() enforces the callback return contract and marks R0\nprecise. R0 is not derived from a real instruction on this path, so\nprecision backtracking reaches the callback call with R0 still requested\nand triggers the \"callback unexpected regs\" verifier bug. A privileged\nprogram loader can therefore cause a verifier warning and an -EFAULT\nBPF_PROG_LOAD.\n\nThese legacy packet-load instructions are deprecated. Reject them from\ncallbacks rather than complicating their implicit-return model. Check all\nactive frames before constructing the implicit return so nested static\nsubprograms cannot hide the callback context.\n\nGlobal functions are verified independently with a fresh frame zero, so\nan active-frame check cannot identify a global function called from a\ncallback. Also check the complete subprogram call graph during stack-depth\nvalidation and reject a function containing a legacy load when any caller\nis a callback. This covers global and static descendants without making\nhas_ld_abs transitive, preserving its per-function BTF return-type check.\nOrdinary uses outside callbacks remain supported."
    }
  ],
  "lastModified": "2026-09-25T11:17:33.200",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}